NIS2 in Portugal — the RJC, MyCiber registration, and a long runway to full measures.
Portugal transposed NIS2 through Decreto-Lei n.º 125/2025 — the Regime Jurídico da Cibersegurança, or RJC — which entered into force on 3 April 2026 and replaced the earlier 2019 framework. The National Cybersecurity Centre (CNCS — Centro Nacional de Cibersegurança) is the single competent authority, with CERT.PT as the national incident-response team. Registration runs through the CNCS MyCiber platform: entities already in scope when the law took effect had 60 working days to register; entities that fall into scope later get 30.
The RJC separates the clocks in a way most transpositions do not. The law and its registration duties are live now, but the full risk-management measures apply only from 22 June 2028, under Regulation 756/2026, in force since 23 June 2026. That makes Portugal one of the longest runways in the Union — and one of the easiest regimes in which to mistake "registered" for "compliant". Fines follow the directive ceilings: up to EUR 10 million or 2% of worldwide turnover for essential entities, EUR 7 million or 1.4% for important ones.
Who it applies to
Essential and important entities across the NIS2 sectors. Registration is through the MyCiber platform — 60 working days for entities in scope at entry into force, 30 days for entities that become subject later. Incident reporting follows the directive standard: 24-hour early warning, 72-hour notification, one-month final report.
The clock
Competent authority: CNCS (Centro Nacional de Cibersegurança). Transposition: Decreto-Lei n.º 125/2025 — Regime Jurídico da Cibersegurança (RJC).
| When | What happens |
|---|---|
| 3 Apr 2026 | RJC (Decreto-Lei n.º 125/2025) enters into force; registration clocks start |
| 23 Jun 2026 | Regulation 756/2026 enters into force — the detailed measures framework |
| 22 Jun 2028 | Full risk-management measures apply |
Two clocks: register now, comply by 2028
Portugal runs the reverse of the last-minute transpositions: the law arrived late — in force 3 April 2026, well past the EU deadline — but gives entities the longest measures runway in the Union, with full obligations only from 22 June 2028. The trap is symmetrical to Bulgaria's: where Bulgaria compressed everything into day one, Portugal lets a completed registration masquerade as compliance. Filing on MyCiber satisfies the first duty and none of the rest. TruSecure holds the two clocks apart — registration status as a dated fact, and the Regulation 756/2026 measures mapped against the 2028 horizon as the planning spine — so the long runway gets used, not absorbed.
What it asks, in operating terms
Read as an operating requirement rather than a legal text, the Portugal transposition reduces to a handful of standing asks — each answerable with evidence on demand, not reconstructed when the authority asks for it.
| What the law asks | Where it is answered |
|---|---|
| Register on MyCiber (60 working days; 30 for new entities) | Entity profile · registration facts held as dated records |
| Implement the Regulation 756/2026 measures by 22 Jun 2028 | Control library · measures mapped and phased to the deadline |
| Report incidents: 24 h, 72 h, one month | Incident workflow · clocked from awareness, stages pre-built |
| Show management responsibility for cybersecurity | Governance workspace · approvals and training records, dated |
| Keep evidence current across a two-year runway | Evidence automation · drift flagged, not discovered at audit |
What you'd actually look at
In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a readiness file is made of:
- MyCiber registration
- filed 22 May 2026 · entity record accepted
- Scope basis
- essential entity · RJC sector classification recorded
- Measures progress
- 61/96 · phased against the Jun 2028 horizon
- Incident reports
- 0 filed · workflow tested, clocks rehearsed
- Export
- sealed · sha256:3c9e...a7f1
Compliance roadmap
Typical timeline: 3–6 months to full compliance readiness
- 1Weeks 1–4
1.Assessment
Gap analysis against NIS2, risk review, remediation plan.
- 2Weeks 5–12
2.Implementation
Controls deployed, policies written, evidence flowing.
- 3Weeks 13–16
3.Audit prep
Gaps closed, evidence package assembled for the authority.
- 4Weeks 17–24
4.Steady state
Continuous evidence, reports on demand, drift alerts.
With TruSecure: 3× faster to audit-ready. AI does the evidence work; your team keeps the decisions.
Where teams usually start
With a demo walked through by TruSecure — your registration position, the Regulation 756/2026 measures mapped against what you already operate, and a phase plan to the June 2028 horizon. Onboarding produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.
TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.
The short answer
NIS2 (Directive (EU) 2022/2555) is enforced in Portugal by CNCS (Centro Nacional de Cibersegurança). TruSecure determines applicability against Portugal's national transposition specifically, rather than the EU baseline alone, and maps its requirements to a single control model shared across every framework it supports. TruSecure is operated by European entities — TRUSECURE S.R.L. in Romania and Trusecure Ltd in the United Kingdom — and stores all Customer Content with a single EU sub-processor in French and German datacenters. No Customer Content is transferred to the United States or to Asia, so the EU–US Data Privacy Framework is not a dependency.